Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0206 — Detection of Malicious Kubernetes CronJob Scheduling
DET0206

Detection of Malicious Kubernetes CronJob Scheduling

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0582 Analytic 0582
Containers

Detects abuse of container orchestration platforms (e.g., Kubernetes) where adversaries create CronJobs to maintain persistence or execute malicious Jobs across the cluster.

kubernetes:apiserver verb=create, resource=cronjobs, group=batch kubernetes:events container start/stop activity via Docker, containerd, or CRI-O container:proxy outbound/inbound network activity from spawned pods
[NamespaceScope] Kubernetes namespace the job is deployed to—scoping this to known trusted namespaces may reduce noise.
[ImageRepository] The container image registry or repository the job pulls from—can be filtered by trusted registries.
[ScheduleWindow] Time window or frequency of CronJob execution (e.g., ‘@hourly’)—jobs running at odd hours may be suspicious.
[ExecutionCommand] The command or entrypoint executed by the Job—unexpected shell commands or interpreters may warrant inspection.

Detected Techniques

1

Details

MITRE ID
DET0206
STIX ID
x-mitre-detection-strategy--a1e17bbb-73d6-48d5-b0ab-1350189b0ecd
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.